-

CVE-2026-64326

block: skip sync_blockdev() on surprise removal in bdev_mark_dead()

In the Linux kernel, the following vulnerability has been resolved:

block: skip sync_blockdev() on surprise removal in bdev_mark_dead()

bdev_mark_dead()'s @surprise == true means the device is already gone.
The filesystem callback fs_bdev_mark_dead() honours this and skips
sync_filesystem(), but the bare block device path (no ->mark_dead op)
lost its !surprise guard when the holder ->mark_dead callback was wired
up (see Fixes), and now calls sync_blockdev() unconditionally, which can
hang forever waiting on writeback that can no longer complete.

syzkaller hit this via nvme_reset_work()'s "I/O queues lost" path:
nvme_mark_namespaces_dead() -> blk_mark_disk_dead() ->
bdev_mark_dead(bdev, true) -> sync_blockdev() blocks in
folio_wait_writeback(), wedging the reset worker and every task waiting
on it.

Skip the sync on surprise removal, matching fs_bdev_mark_dead();
invalidate_bdev() still runs. Orderly removal (surprise == false) is
unchanged.

Found by FuzzNvme(Syzkaller with FEMU fuzzing framework).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version d8530de5a6e82be0ce17a5fdf727a394bcf6444c
Version < d6998ddd507c81e3829489a6ead23f17f5acb7fe
Status affected
Version d8530de5a6e82be0ce17a5fdf727a394bcf6444c
Version < f41cf35ee2a1e31374b3f54e7579c55153506e70
Status affected
Version d8530de5a6e82be0ce17a5fdf727a394bcf6444c
Version < 9818bcae3c0ca1dde4b9a334125c46676e0a9b29
Status affected
Version d8530de5a6e82be0ce17a5fdf727a394bcf6444c
Version < aa4c4a9315764b2b7a7182e72cc5ea87520436b4
Status affected
Version d8530de5a6e82be0ce17a5fdf727a394bcf6444c
Version < 49f06cff50a4ccf3b7a1a662ceb892b3b21a527a
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d6998ddd507c81e3829489a6ead23f17f5acb7fe
https://git.kernel.org/stable/c/f41cf35ee2a1e31374b3f54e7579c55153506e70
https://git.kernel.org/stable/c/9818bcae3c0ca1dde4b9a334125c46676e0a9b29
https://git.kernel.org/stable/c/aa4c4a9315764b2b7a7182e72cc5ea87520436b4
https://git.kernel.org/stable/c/49f06cff50a4ccf3b7a1a662ceb892b3b21a527a